WEST-SEC ã»ãã¥ãªãã£å匷äŒïŒãã³ãºãªã³ïŒ
ã€ãã³ãå 容
ãåéå¬ãWEST-SEC ã»ãã¥ãªãã£å匷äŒïŒ
ç¿é±ïŒ1/31ïŒã«éå¬ããWEST-SECã«åãããäºåã®ã»ãã¥ãªãã£å匷äŒã宿œããŸãã
å匷äŒã®ç®çã¯ãCTFãè§£ãããã®ç¥èã身ã«çããããšã ãã§ã¯ãããŸããã
æã
ã®CTFã®ç®çã¯ã瀟äŒäººããã³æ
å ±ã·ã¹ãã éšã«ãããŠå¿
èŠãªã»ãã¥ãªãã£ç¥èãé«ããããšã§ãã
ãã£ãŠããã®å匷äŒãWEST-SEC CTFãšç®çãåãã§ã瀟äŒã§å¿
èŠãªã»ãã¥ãªãã£ç¥èãé«ããããšã§ãã
ãªã®ã§ãCTFãè§£ãããã®éå»åã玹ä»ãããããã¯ããã¯ã®ç޹ä»ã¯äžåãããŸããã
ããããæå³ã§ã¯ãäžè¬çãªã»ãã¥ãªãã£å匷äŒãšèããŠããã£ãæ¹ãè¿ããšæããŸãã
ãšã¯ããããã®å匷äŒãéããŠãWEST-SEC CTFã®çè§£ã«ã€ãªããããšã¯ééããããŸããã
æŽçãããšããã®å匷äŒã®ç®çã¯ä»¥äžã§ãã
ã»ã»ãã¥ãªãã£ã«é¢ããå¹
åºãåºç€ç¥èãåŠç¿ããŠããã ãã
ã»ïŒäºååŠç¿ãçµéšããããšã§ãïŒååŠè
ã®çããã®ãCTFåå ãžã®ããŒãã«ãäžããã
ã»åå è
ã®åºç€ã¹ãã«ã¬ãã«ãåäžãããããšã§ãCTFæ¬æŠããããæ¥œããã§ããã ãã
ã»ïŒäºåå±ãšããŠã¯ãïŒCTFã§ã¯ãªãçŽç²ãªå匷äŒã®ããŒãºãã©ãããããããã®ç¢ºèªãããã
åæç¥è
以äžãç¥èããªããŠãåå ã§ããŸãããç¥ã£ãŠããåæã§è¬çŸ©ãé²ããŸãã
ã»ITãã¹ããŒãã«ç»å Žããåºæ¬çãªçšèªããååãããç¥ã£ãŠããã
ã»ç¹ã«ITãã¹ããŒãã«ç»å Žããã»ãã¥ãªãã£ã®çšèªãæŠãç¥ã£ãŠããïŒãŸãã¯åœæ¥ãŸã§ã«ããã£ãšå匷ããïŒ
çšèªäŸãšããŠã¯ããã«ãŠã§ã¢ãããã¯ãã¢ãã»ãã¥ãªãã£ããŒã«ãè匱æ§ããã«ãŒããã©ãŒã¹æ»æãã¯ãã¹ãµã€ãã¹ã¯ãªããã£ã³ã°ããã£ã¬ã¯ããªãã©ããŒãµã«ããŒããã€æ»æãã»ãã·ã§ã³ãã€ãžã£ãã¯ãWAFãUTMãªã©ã
ã»å¯èœã§ããã°ãPKIïŒå
¬ééµãç§å¯éµããã£ãžã¿ã«çœ²åãèšŒææžïŒã®åºç€ç¥èããããšãããããã§ãã
以äžãèªãã§ã»ããã§ããïŒ5åãããã§èªããŸãïŒ
https://www.nrapki.jp/client-certificate/about-pki/
ãå 容ã
ã»çŸåšãã«ãªãã¥ã©ã ãæ€èšäžãªã®ã§ãå
容ã¯å€æŽãããšæããŸãã
ã»ä»¥äžãããããã®ã§ãããããããæéãè¶³ããªãã®ã§ãå
容ãå°ãã¹ãªã ã«ãããšæããŸãã
ã»çããã®PCã«ããã°ã©ã ã®å®è¡ç°å¢ãLinuxãµãŒããæ§ç¯ããŠãããããšããã®ã§ãããé£ãã人ããããšæããŸãããã£ãŠãçããã«ã¯å
±éã®AWSç°å¢ããæž¡ããã8å²ãããã®å
容ã¯å®æ©æäœããŠããããããã«æºåããŸãã
ã»è³æã¯é
åžããŸãããããããããçè§£ãã ããã
1.Linuxã®åºæ¬æäœã10å
(1)Teratermã«ããSSHæ¥ç¶
(2)Linuxã®åºæ¬æäœ
ãã»åçš®ã³ãã³ã
ãã»viãšãã£ã¿
ãã»ãã¡ã€ã«ã®ã¢ããããŒããšããŠã³ããŒã
2.ããã°ã©ã ã20å
(1)PHP
ãã»ç°å¢æ§ç¯
ãã»PHPã«ããç°¡åãªããã°ã©ã äœæ
(2)Python
ãã»ç°å¢æ§ç¯
ãã»ç°¡åãªããã°ã©ã äœæ
(3)Cèšèª
ãã»ç°å¢æ§ç¯
ãã»Cã«ããç°¡åãªããã°ã©ã ã®äœæ
(4)ãããã¡ãªãŒããããŒ
ãã»ãããã¡ããŒã®ä»çµã¿
ãã»ãããã¡ããŒã®å®æŒïŒåæ©ïŒ
3.æå·ãã15å
(1)æå·ã®ä»çµã¿
ãã»ãããããªæå·ã玹ä»ã宿Œ
(2)ãšã³ã³ãŒããšã¯
ãã»BASE64
ãã»ããŒã»ã³ããšã³ã³ãŒãã£ã³ã°
(3)ããã·ã¥é¢æ°
ãã»ããã·ã¥é¢æ°ã®ä»çµã¿
ãã»ããã·ã¥ããå
ã®ããŒã¿ãæ¢ã
(4)RSAæå·
ãã»ä»çµã¿ã®è§£èª¬
4.ãããã¯ãŒã¯ã15å
(1)ãããã¯ãŒã¯åºç€
(2)Wiresharkåºç€
ãã»ã€ã³ã¹ããŒã«ãšèµ·å
ãã»ãã£ã«ã¿ã®èšå®
ãã»ãã¡ã€ã«ã®ååŸ
(3)nmap
(4)DNS
ãã»DNSã®åºæ¬çšèª
ãã»nslookupã«ããåå解決
5.FirewallãšFortiGateã15å
(1)Firewallã®åºæ¬èšèš
ãã»Firewallã®åœ¹å²
ãã»ããªã·ãŒèšèšãšèãæ¹
(2)FortiGateã®æäœ
ãã»ãã°ã€ã³
ãã»ããªã·ãŒèšå®
ãã»UTMèšå®
ãã»ãã°ã®ç¢ºèª
6.Webã¢ããªã±ãŒã·ã§ã³ã25å
(1)HTTPãããã³ã«
ãã»HTTPãªã¯ãšã¹ããšã¬ã¹ãã³ã¹
ãã»HTTPããã
ãã»GETã¡ãœãããšPOSTã¡ãœãã
(2)Cookieãšã»ãã·ã§ã³ç®¡ç
ãã»PHPããã°ã©ã ã«ããã»ãã·ã§ã³ç®¡ç
(3)ããŒã¿ããŒã¹æ§ç¯
ãã»mysqlã®ã€ã³ã¹ããŒã«
ãã»ããŒãã«äœæ
ãã»SQLã®å®è¡
(4)SQLã€ã³ãžã§ã¯ã·ã§ã³
7.è§£æã30å
(1)ãã°è§£æ
ãã»apacheã®ãã°ã®ç¢ºèª
ãã»ãã°åæã®å®æŒ
(2)ãã€ããªè§£æ
ãã»ãã€ããªè§£æãšã¯
ãã»ãã€ããªè§£æã®ããŒã«
ãã»ãã€ããªè§£æã®å®æŒ
(3)ã¡ã¢ãªãã©ã¬ã³ãžãã¯
ãã»ã¡ã¢ãªãã©ã¬ã³ãžãã¯ãšã¯
ãã»ã¡ã¢ãªãã©ã¬ã³ãžãã¯ã®ããŒã«
ãã»ã¡ã¢ãªãã©ã¬ã³ãžãã¯ã®å®æŒ
8.æ³åŸã5å
ã»å人æ
å ±ä¿è·æ³
ã»äžæ£ã¢ã¯ã»ã¹çŠæ¢æ³
ãªã©
åå 察象è
ç¹ã«å¶éã¯ãããŸãããã以äžã®æ¹ãæèããŠãããŸãã
ã»æ
å ±ã·ã¹ãã éšéã§ã»ãã¥ãªãã£å¯Ÿçã®åºç€ãæ¹ããŠå確èªãããæ¹
ã»ã»ãã¥ãªãã£ã«èå³ããããã»ãã¥ãªãã£å¯Ÿçããã£ãšæ·±ãç¥ãããæ¹ãïŒâ»åŠçãã倧æè¿ïŒ
ã»ãã®ç ä¿®ã§åŸãç¥èãã»ãã¥ãªãã£å¯Ÿçã®ã¿ã«æŽ»ãããæªçšããªãæ¹
âã€ãŸããéãšã³ãžãã¢ã®æ¹ãã»ãã¥ãªãã£ã®ååŠè
ã倧æè¿ã§ãïŒ

å¿ èŠãªãã®
ã»ãã©ãŠã¶ïŒGoogle Chromeãªã©ãIEãEdgeã¯éæšå¥šïŒãå
¥ã£ãã€ã³ã¿ãŒãããã«æ¥ç¶ã§ããPCãã¹ããŒããã©ã³ããã®åå ãå¯èœã§ãããSSHæ¥ç¶ããã°åæãªã©ãããŠããã ããããäžéšã®ç«¶æã®åå ãå³ãããšæããŸãã
ã»WebäŒè°ããŒã«ïŒCiscoWebEXãZOOMãªã©ïŒã®ç°å¢ã
ã»TeraTermãªã©ã®SSHã«æ¥ç¶ããããŒã«ïŒç¡ãå Žåã¯äžéšã®åé¡ãè§£ãããšãã§ããŸããããããŒã æŠãªã®ã§ç»é¢å
±æçã§ãäºãã«ãã©ããŒããŠããã ããšããæããããŸããïŒ
ã»ãã±ãããã£ããã£ã®ãœããã§ããWiresharkïŒãããïŒ
ãé¡ã
ã»ä»åŸã®ã«ãªãã¥ã©ã ãéå¶ã®åäžã®ããã«ã¢ã³ã±ãŒãããé¡ãããŸãã
ã»åœæ¥ã®ææ³ãããã°ãfacebookãTwitterãªã©ã®SNSã«æçš¿é¡ããŸããæçš¿ããŠãããããšããšãŠãããããã§ãã
åœæ¥ã®æµã
ïŒïŒïŒã¿ã€ã ã¹ã±ãžã¥ãŒã«ïŒäºå®ïŒ
| é çª | æå» | å 容 |
|---|---|---|
| Program0 | 18:55~ã | WebäŒè°ã®éšå±ã空ããŸãã |
| Program1 | 19:00 ~ 21:15 | è¬çŸ© ã¢ã³ã±ãŒãèšå ¥ |
| Program2 | çµäºåŸ | åœæ¥ã®ææ³ãããã°ãfacebookãTwitterãªã©ã®SNSã«æçš¿é¡ããŸãã |
è¬åž«
ã»ç²æ·µ å ã»è€ç° æ¿å
泚æäºé
â» ãã¡ãã®ã€ãã³ãæ å ±ã¯ãå€éšãµã€ãããååŸããæ å ±ãæ²èŒããŠããŸãã
â» æ²èŒã¿ã€ãã³ã°ãæŽæ°é »åºŠã«ãã£ãŠã¯ãæ å ±æäŸå ããŒãžã®å 容ãšå·®ç°ãçºçããŸãã®ã§äºããäºæ¿ãã ããã
â» ææ°æ å ±ã®ç¢ºèªãåå ç³èŸŒæç¶ããã€ãã³ãã«é¢ãããåãåããçã¯æ å ±æäŸå ããŒãžã«ãŠãé¡ãããŸãã

ãåãåãã
é¢é£ããã€ãã³ã

ãç¡æãæ¥åèªååãã人工ç¥èœãŸã§ïŒå®è·µPythonããã°ã©ãã³ã°äœéšã»ãããŒ-æãåãããŠåŠã¶Pythonã¯ãŒã¯ã·ã§ãã-
2026/04/26(æ¥) éå¬
4/19ãçŸåœ¹ãšã³ãžãã¢ã®ç¡æãã£ãªã¢çžè«ä»ããAIç«¶äºã§éèŠæ¥å¢äžã®ãPythonããåŠãã§ãã£ãªã¢ã¢ãããç®æãã in æ±äº¬
2026/04/19(æ¥) éå¬
4/20ãçŸåœ¹ãšã³ãžãã¢ã®ç¡æãã£ãªã¢çžè«ä»ããAIç«¶äºã§éèŠæ¥å¢äžã®ãPythonããåŠãã§ãã£ãªã¢ã¢ãããç®æãã in æ±äº¬
2026/04/20(æ) éå¬
ITã€ã³ãã©éçšèªååããŒã«POLESTAR Automation ããŒãå¥Webã»ãããŒããä»åã®ããŒãã¯ãèšå®å€æŽã®ç£æ»ãšäžæ£æ€ç¥ã
2026/06/25(æš) éå¬
4/7 çæAIè¬åº§ãéè¬ïŒPythonã§AIã䜿ã£ãã¢ããªãäœæããæ¹æ³ãåŠã¶ç¡æäœéšè¬åº§ in æ±äº¬
2026/04/07(ç«) éå¬- TOP
- ã€ãã³ã
- WEST-SEC ã»ãã¥ãªãã£å匷äŒïŒãã³ãºãªã³ïŒ
